An Innocent Everyday Threat
How FM manages the wearable-ready facility
For a decade, workplace security policy has rested on a convenient assumption that recording is a visible act. Someone takes out a phone, opens a laptop, lifts a camera. Because everyone in the room can see the gesture, it can be challenged or designed around.
Consumer wearables dissolve that assumption, and smart glasses and AI wearables are only the most conspicuous example. The current generation of wearables look close enough to ordinary eyewear or pendants and bands to pass without comment. Earbuds, clip-on recorders, smartwatches, rings and fitness trackers carry overlapping capability in packages that attract even less scrutiny.
None of this was designed as workplace equipment, which makes it a facilities challenge. These are consumer goods, bought personally and worn casually, and employees, contractors and visitors bring them through the door the way they bring a watch. An organization that never purchases a single device may still find dozens operating in meeting rooms, plant areas and laboratories.
The governing question for facility management teams becomes what sensing capability each space can tolerate, rather than which devices to approve.
From gadget to everyday interface
Manufacturers stopped making the technology impressive and started making it invisible, putting it inside frames and accessories people already wanted to own. Counterpoint Research put the leading vendor at roughly 85 percent of global smart glasses shipments in 2025, on volume near 8.7 million units.
Four capabilities are converging across the category:
-
Devices are becoming hard to distinguish from ordinary clothing, eyewear and jewelry.
-
Cameras and microphones have moved from the hand to the body.
-
AI now interprets what is captured rather than merely storing it.
-
Devices are available all day with almost no conscious interaction.
The wearables that are not glasses
Eyewear draws the most attention because a camera on the face is easy to picture, but other categories deserve equal scrutiny.
In January 2018, a public heatmap from a fitness application exposed the perimeters, internal paths and patrol patterns of military bases in Syria, Iraq and Afghanistan, drawn from the exercise routes of personnel there. No camera was involved, and the layouts became public.
A new form of workplace visibility
Buildings are full of information nobody has classified as data: from whiteboards mid-meeting, documents on desks, badges, control panels, evacuation plans and camera positions.
A wearable camera collects this incidentally as its user walks through a space, and AI can then transcribe, translate or summarize it. Research on egocentric perception, including the multi-university Ego4D dataset, trains models on continuous first-person video, producing systems that read text from the environment and answer questions about it.
Unauthorized capture once required a visible action that colleagues could notice and staff could interrupt. Now, a visitor wearing smart glasses can photograph a restricted installation while simply appearing to look, and a visitor with a recorder does not need to look at all.
Most incidents will be accidental rather than hostile, and the accidental incident is harder to police. Someone asks a device to remember a slide, translate a supplier's remarks or identify a piece of equipment, with no sense that the data has left the building for a third-party server.
Privacy without a clear boundary
Wearables create an unusual privacy problem because the person who consented is not the person most affected. The wearer read the terms and chose to put the device on; the colleagues and visitors it captures did not.
Governance around a fixed workplace camera is well established: the organization decides where it points, who sees the footage and how long it is kept, and signage explains that monitoring occurs. A personally owned wearable is mobile, individually controlled and tied to a cloud account the organization cannot see into.
Concern rises once people grasp what biometric data can reveal. A survey of eye-tracking privacy by Kröger and colleagues catalogs the inferences available from gaze data alone: biometric identity, age, gender, personality traits, cognitive load, emotional state and health conditions.
A cultural cost arrives before any recording does. One person's assistive device changes the room for everyone. People behave differently around a device they believe might be listening, and meetings get less candid.
Access control answers only half the question
FM and security teams have historically asked whether a person may enter a space. A valid access card says nothing about whether everything that person is wearing belongs in the room.
Exposure varies sharply by environment, and zoning should follow it. A general office holds confidential discussion, personal data and screens. Research facilities put intellectual property and prototypes in front of the lens. In manufacturing and critical infrastructure, images of control interfaces and layouts reveal how an operation works and where it is weak. Health care, education and public-facing settings carry duties toward patients, children and service users, while restrooms and changing areas carry privacy expectations that make restrictions absolute.
Audio recording adds legal complexity that varies sharply by jurisdiction. Some countries, and some states within them, require the consent of every party before a conversation may be recorded, while others require only one. Several jurisdictions regulate biometric collection specifically, some allowing individuals to sue directly. Any organization operating across borders should assume a single global wearable policy will fail somewhere.
Data protection regulators have set out principles that travel well. Guidance on monitoring workers published by the U.K. Information Commissioner's Office in 2023 directs organizations to identify a lawful basis, consider less intrusive alternatives and assess impact where monitoring is high risk.
The policy gap
Most organizations believe they have covered this because their policy prohibits unauthorized photography and recording. The reality is that usually they have not.
Policies written around cameras and phones rarely mention glasses, earbuds, pins or rings with sensors, and staff read that omission as permission. Employees do not classify an AI query as a disclosure, and asking an assistant to summarize a whiteboard feels different from photographing it, though the information leaves either way.
A rule naming specific products will be obsolete within two cycles, while a rule addressing any device that captures, transmits, analyzes or augments visual, audio, biometric or location information will survive the next form factor.
Possession and use must also be separated, because prohibiting ordinary-looking wearables across an entire site is hard to enforce, and potentially discriminatory against people who rely on the technology for accessibility.
Building a wearable-ready workplace
The first step is assessing the property portfolio for what a wearable could sense in it. FM, security, IT, privacy, legal, HR and business units must agree where recording or AI interpretation would cause material harm. Typical candidates include research and development areas, operations centers, board rooms, production lines, records storage and treatment spaces.
Most portfolios then sort into three tiers, which map onto physical-security zoning many organizations already operate.
Tiering is easier to explain and enforce than a site-wide ban, because it identifies where the line falls.
Visitors & contractors
Visitors and contractors have had no internal training and no reason to expect the rules. Restrictions involve booking confirmations and confidentiality agreements, so people learn about them before arrival. Reception staff should be trained to recognize categories of devices, not every model on sale.
Signage must also be reconsidered, because a crossed-out camera icon means nothing to a visitor wearing a recorder that has no camera. Instead, it should describe prohibited functions. Where risk justifies it, organizations can provide secure storage and a documented route for accessibility needs.
Incident response
Incident plans should cover wearable scenarios before they are needed. An employee records a confidential meeting, or a visitor livestreams from a controlled area. A transcript syncs to a personal cloud account, or a device goes missing after a site visit.
The response must establish what was captured, whether it was transmitted, which service processed it and what reporting obligations apply.
The device is a risk
Wearables communicate over Bluetooth and Wi-Fi and depend on a paired mobile app, which surfaces familiar weak points: authentication, insecure pairing, encryption and patching. Guidance from the U.S. National Institute of Standards and Technology (NIST) on IoT risk argues for managing such devices across their full life cycle, because the hardware often cannot support conventional controls. Personally owned wearables should not join corporate or building-management networks by default, and guest-network arrangements and wireless segmentation warrant review.
Avoiding an anti-technology response
None of this should harden into a presumption that wearable users are security risks. The same hardware generates live captions, translates conversations and helps people navigate unfamiliar buildings, while continuous health monitoring has legitimate safety uses in hazardous environments. For some employees, those functions decide whether they can participate in a meeting at all.
Restriction should therefore track the sensitivity of the location and activity, not discomfort with unfamiliar hardware. Policies should build in exceptions and allow risk assessments that permit a device with specific functions disabled.
Why this belongs with FM
Consumer wearables fall between departments, which is how they end up owned by nobody. IT sees personal devices outside its remit, HR sees a conduct question, legal sees privacy law, and security sees a prohibited camera. FM is where those views reconcile, because the risk is a function of the physical environment. FM teams know how people move through a building, which rooms hold sensitive activity, and where occupants expect privacy.
Preparing for ambient computing
Today's wearables record, listen, translate and answer questions, and the next generation adds agents that act on what they observe. Waiting until that is ubiquitous means inheriting whatever informal norms form in the meantime, and those are harder to change than absent ones. The organizations that manage this well will be the ones that decided in advance which rooms matter, said so clearly and left the rest alone.
Marcus Elendu is a technical program manager and analytics practitioner specializing in enterprise workplace systems and Integrated Facilities Management technology. He has spent his career at the intersection of facilities operations and data, leading the implementation and management of analytics platforms, automation initiatives and workplace technology stacks for global IFM teams.
References
Additional resources:
Counterpoint Research, global smart glasses shipment share, 2025 — https://counterpointresearch.com/en/insights/Global-Smart-Glasses-Shipments-Grew-139-Percent-YoY-in-H2-2025
Privacy International, "Strava fitness app exposes jogging routes around military bases" — https://privacyinternational.org/examples/1946/strava-fitness-app-exposes-jogging-routes-around-military-bases
Kröger, J. L., Lutz, O. H.-M., and Müller, F. (2020), "What Does Your Gaze Reveal About You? On the Privacy Implications of Eye Tracking," IFIP AICT vol. 576, Springer — https://link.springer.com/chapter/10.1007/978-3-030-42504-3_15
Information Commissioner's Office, "Employment practices and data protection: monitoring workers," 2023 — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/
NIST IR 8228, Considerations for Managing IoT Cybersecurity and Privacy Risks — https://csrc.nist.gov/pubs/ir/8228/final
Top image via Getty Images.
Read more on Facility Technology & Data Management and Risk Management or related topics Information Technology , Cybersecurity , Policy and Occupant Security
Explore All FMJ Topics